CVE-2026-38754: BusyBox Heap Overflow DoS on Azure

🟡 Medium | Source: Microsoft Security Response Center A heap overflow vulnerability has been identified in the ifsbreakup() function within BusyBox v1.38.0’s shell component (ash.c), tracked as CVE-2026-38754. An attacker can exploit this by supplying specially crafted input to trigger a Denial of Service condition. BusyBox is widely used in lightweight Linux environments, including container base images and IoT firmware, making this relevant to many Azure-hosted workloads. Security Architect’s Take: Audit your container base images and any Azure infrastructure components that bundle BusyBox v1.38.0, and prioritise updating to a patched version. Pay particular attention to AKS node pools and container registries where BusyBox-based images may be in active use. ...

21 July 2024 · ZX Cloud Security

CVE-2026-63828: AppArmor TCP Fast Open Bypass on Azure

🟡 Medium | Source: Microsoft Security Response Center CVE-2026-63828 is a Linux kernel vulnerability relating to AppArmor’s failure to mediate implicit TCP connections made via the TCP Fast Open (TFO) sendmsg path. This means that AppArmor security policies intended to restrict network access could be bypassed for certain outbound TCP connections, potentially allowing processes to communicate with endpoints they should be prohibited from reaching. The issue affects Linux-based Azure workloads where AppArmor is used as a mandatory access control mechanism. ...

21 July 2024 · ZX Cloud Security

CVE-2026-64146: Linux EROFS Metabuf Leak on Azure

🟡 Medium | Source: Microsoft Security Response Center CVE-2026-64146 is a memory leak vulnerability in the Linux kernel’s EROFS (Enhanced Read-Only File System) implementation, specifically in the inode extended attribute (xattr) initialisation routine. A metadata buffer is not properly released under certain conditions, which could lead to resource exhaustion or, in some scenarios, expose sensitive data left in unfreed memory. This affects Linux-based Azure workloads, including virtual machines and containerised services running affected kernel versions. ...

21 July 2024 · ZX Cloud Security

CVE-2026-63882 Azure Linux AMD GPU NULL Pointer Fix

🟡 Medium | Source: Microsoft Security Response Center CVE-2026-63882 is a NULL pointer dereference vulnerability in the Linux kernel’s AMD GPU driver component (drm/amdkfd), specifically within the svm_range_set_attr function used for shared virtual memory management. While originating in the Linux kernel, this vulnerability is relevant to Azure environments running Linux VMs with AMD GPU instances. If exploited, it could cause a kernel crash or potentially be leveraged for privilege escalation on affected workloads. ...

21 July 2024 · ZX Cloud Security

CVE-2026-63940: KVM SEV Port I/O Flaw on Azure

🟡 Medium | Source: Microsoft Security Response Center CVE-2026-63940 is a vulnerability in the Linux Kernel Virtual Machine (KVM) hypervisor relating to how AMD Secure Encrypted Virtualisation (SEV) handles Port I/O requests of zero length. Improper handling of these edge-case requests could potentially be exploited to cause unexpected behaviour in virtualised environments. This is relevant to Azure as Microsoft’s underlying infrastructure relies on virtualisation technologies, and SEV is increasingly used to protect confidential computing workloads. ...

21 July 2024 · ZX Cloud Security

CVE-2026-64097 AMD Display Driver Linux Kernel Flaw

🟡 Medium | Source: Microsoft Security Response Center CVE-2026-64097 is a vulnerability in the AMD display driver subsystem (drm/amd/display) within the Linux kernel, relating to a missing bounds check on a GPIO pin Look-Up Table (LUT) before iteration. Without proper validation of the table size, out-of-bounds memory access could occur, potentially leading to information disclosure or system instability. This affects Linux-based environments, including Azure virtual machines and services running Linux with AMD GPU drivers. ...

21 July 2024 · ZX Cloud Security

CVE-2026-64133: Linux ALSA OOB Fix in Azure

🟡 Medium | Source: Microsoft Security Response Center CVE-2026-64133 is a vulnerability in the Linux kernel’s ALSA audio subsystem, specifically the ASI HPI driver, where an out-of-bounds (OOB) array access can occur when reading cached data. While originating in the Linux kernel, this advisory has been published by Microsoft, indicating relevance to Azure environments — likely affecting Linux-based virtual machines or services running on Azure infrastructure. Out-of-bounds memory access flaws can potentially be exploited to read sensitive data or destabilise affected systems. ...

21 July 2024 · ZX Cloud Security

FBI IC3 Impersonation Scams Target Crime Victims

🟡 Medium | Source: The Register — Security Scammers are impersonating the FBI’s Internet Crime Complaint Center (IC3) on social media platforms, targeting individuals who have already fallen victim to cybercrime. The IC3 has issued a warning clarifying that it operates no official social media accounts, meaning any account claiming to represent it is fraudulent. These scams typically aim to extract further money or personal information from victims under the guise of assisting with their original complaint. ...

20 July 2024 · ZX Cloud Security

Frontier LLMs Fail Defensive AI Agent Tasks | GLM 5.2

🟡 Medium | Source: The Register — Security Hugging Face researchers found that leading frontier large language models (LLMs) refused to assist in defending against malicious AI agents due to overly cautious safety guardrails, while Chinese open-weight model GLM 5.2 complied without issue. This highlights a practical tension between AI safety alignment and legitimate defensive security use cases. The findings raise concerns about whether safety-focused models are becoming less useful for blue-team security operations. ...

20 July 2024 · ZX Cloud Security

AI Phishing Toolkit Exposed: WebDAV Malware Campaign

🟡 Medium | Source: The Hacker News A threat actor accidentally exposed their malware staging server, allowing Rapid7 researchers to download over 1,000 files revealing a sophisticated, AI-assisted phishing toolkit. The toolkit includes lure templates, droppers, and two active campaign chains — one already targeting Windows users in Mexico via a fake government website delivering an infostealer over WebDAV. The exposure provides rare visibility into a modern, AI-augmented attack workflow from initial lure creation through to payload delivery. ...

20 July 2024 · ZX Cloud Security

📬 Stay Informed

Get daily cloud security advisories delivered to your inbox.

Free. No spam. Unsubscribe anytime. View subscription options